CVE-2026-75808 Details
Description
Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an unrestricted amount of memory.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
A denial-of-service vulnerability has been identified in ASUS Armoury Crate, specifically in versions through 6.5.7.0. This vulnerability allows a local user to cause system memory exhaustion, leading to a denial-of-service condition. The issue arises from the allocation of resources without proper limits or throttling, allowing an unrestricted amount of memory to be allocated. This memory exhaustion can bypass driver authentication, exacerbating the denial-of-service condition.
Users are advised to update to the latest version of ASUS Armoury Crate. The latest version can be downloaded from the ASUS Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asus.com/security-advisory | ASUS | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | ASUS |
Affected Products
| Product | Versions |
|---|---|
| ASUS Armoury Crate | <= 6.5.7.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | ASUS |
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | ASUS |
Volerion